cancel
Showing results for 
Search instead for 
Did you mean: 
Reply
FabianAckeret
Solution Sage
Solution Sage

Unauthorized: Graph API - Create Planner Plan

Dear community

 

I'd like to create a Planner plan with Flow and found this article. I went ahead and configured Azure accordingly (which I know it works since I can create a team the same way with Flow). In this video, he explains how to create a plan with the Graph Explorer. This works perfectly - I can create a Planner plan with the Graph Explorer, but I can't get it to work with the HTTP action in Flow. I assume it's because the Graph Explorer runs the code in the user context and the HTTP action does not. How can I run it with the tenant id/client id/client secret?

 

This is how my Flow looks like: 

planner.png

 

And I get this error message whenever I run it:

401 - Unauthorized: Access is denied due to invalid credentials.

 

** Edit **

Can you even do that with Flow? Since it only supports delegated api calls?


Please click Accept as Solution if my post answered your question. Like my answer? Consider giving it a Thumbs Up. Others seeking the same answers will be happy you did.
1 ACCEPTED SOLUTION

Accepted Solutions

Hi

 

That post is from back in the days when Planner plans came along with SharePoint sites. However, since no Planner plan will be provisioned whenever a SharePoint site is being created, this blog post doesn't cover the most important part.

 

Anyway, I've figured it out. I hope this helps some people 🙂

 

  1. Configure Azure AD App Permissions with Delegated Group.ReadWrite.All (see MS doc)
  2. Since the "application" permission-type is not supported, you'd need to run it with a user-context. You can do that by creating an HTTP action and use that Authorization token according to the screenshot below. I'm adding a service account to the group since you can only create a plan when you're also part of it.
    You can copy the "Parse JSON - get access token" action-Schema here:
    {
        "type": "object",
        "properties": {
            "token_type": {
                "type": "string"
            },
            "expires_in": {
                "type": "string"
            },
            "ext_expires_in": {
                "type": "string"
            },
            "expires_on": {
                "type": "string"
            },
            "not_before": {
                "type": "string"
            },
            "resource": {
                "type": "string"
            },
            "access_token": {
                "type": "string"
            }
        }
    }
    access-token-planner-plan.png

 

Cheers


Please click Accept as Solution if my post answered your question. Like my answer? Consider giving it a Thumbs Up. Others seeking the same answers will be happy you did.

View solution in original post

8 REPLIES 8
v-bacao-msft
Community Support
Community Support

 

Hi @FabianAckeret ,

 

Please check this article and see if it helps:

https://daytodaydynamics365.com/creating-a-planner-plan-from-a-d365-psa-project-with-flow/

 

Best Regards,

Community Support Team _ Barry
If this post helps, then please consider Accept it as the solution to help the other members find it more quickly.

Hi

 

That post is from back in the days when Planner plans came along with SharePoint sites. However, since no Planner plan will be provisioned whenever a SharePoint site is being created, this blog post doesn't cover the most important part.

 

Anyway, I've figured it out. I hope this helps some people 🙂

 

  1. Configure Azure AD App Permissions with Delegated Group.ReadWrite.All (see MS doc)
  2. Since the "application" permission-type is not supported, you'd need to run it with a user-context. You can do that by creating an HTTP action and use that Authorization token according to the screenshot below. I'm adding a service account to the group since you can only create a plan when you're also part of it.
    You can copy the "Parse JSON - get access token" action-Schema here:
    {
        "type": "object",
        "properties": {
            "token_type": {
                "type": "string"
            },
            "expires_in": {
                "type": "string"
            },
            "ext_expires_in": {
                "type": "string"
            },
            "expires_on": {
                "type": "string"
            },
            "not_before": {
                "type": "string"
            },
            "resource": {
                "type": "string"
            },
            "access_token": {
                "type": "string"
            }
        }
    }
    access-token-planner-plan.png

 

Cheers


Please click Accept as Solution if my post answered your question. Like my answer? Consider giving it a Thumbs Up. Others seeking the same answers will be happy you did.

Hi isabasu,

i have been stuck with this issue for a whole day now.

i have registered an app in azure and have all the neccessary token values. and using the same app i am able create a group successfully that is required prior to create a plan.

 

however while trying create a plan in next step using a group id from previous step, i am getting a same error as you have mentioned.

 

following your reply i am able to get an authorization token but i am stuck with additional step you have performed of adding a SERVICE USER to an AZURE group.

i assume with service user you are referring to an APP we have registered earlier?

but which azure group you have added that user to? isnt the group id required is of an O365 group?

 

i would appriciated you help becuase i dont see many people have blogged/explained issues related to creating a plan using graph api.

many thanks.

@KhurramJamshed 

 

Sure thing.

With a service user, I just meant a normal user account dedicated to tasks like this. You can call him donald.duck@domain.com if you like. For testing purposes, I have assigned global admin permissions to that service user. 

 

In Planner, you can't create a plan if you are not part of that O365 group you'd like to create it for. That is why, before Flow is trying to create the plan, you'd need to add the user to that O365 group.

 

You mentioned that you were able to create an O365 group, right? Everything after that is actually quite simple.

Just use the flow Azure AD action "Add user to group". Since you have the id of the group as well as the one from the user, that shouldn't be a problem. 

 

Once you have that, you can call the HTTP Web Service to create a planner plan according to my screenshot in the previous post. 

 

 


Please click Accept as Solution if my post answered your question. Like my answer? Consider giving it a Thumbs Up. Others seeking the same answers will be happy you did.

thanks for replying @FabianAckeret  - in that case, i dont see what is missing at my end. except for the way you did a few things i.e. adding a user to a group using AD action. which i did while creating a group

 

FlowGroup.PNG

 

i will give another try by adding user using AD group action and let you know.

Hi,

I am using PowerShell to create planner by calling Graph API. As mentioned in this article registered the app with all required Delegated permissions including admin consent. 

Running the script with a service account. Able to get the auth token . But at the command 

 

$planner = New-PlannerPlan -PlanName $plannerTitle -visibility $plannerVisibility

 

it is giving below error :

Get-PlannerAuthToken : Authorization Access Token is null, please re-run authentication...

And sometimes its creating group but throwing below error while creating the plan with group id

Request to https://graph.microsoft.com/beta/planner/plans failed with HTTP Status Forbidden Forbidden

Can someone help in understanding what could be the cause..?

Also, can a service account ( which has SharePoint, Teams, Exchange admin roles along with a Group Creation permission ) create the plan by connecting to planner with regular credentials without auth token/app registration path in azure?

 

Thank you,

Purna

Hello

Thanks @FabianAckeret  I use your topic to create the connection to Graph Api

 

But I have two call one for create a Plan a second to get the groups URL. This task works fine but sometimes without explain I have authorization Error

For the Get Groups Url I have the error randomly "access denied"

For the Create Plan, the error "You do not have the required permissions to access this item, or the item may not exist."

 

If I use this task in 2 different flow, its work fine, in the same flow I have randomly this error and I dont understand why ?

 

 

 

Hi @BastienB 

 

I would even do it entirely different than in my previous post nowadays. 

This post explains how I would do it. Create an app registration, get the client id & client secret, and add it to the OAuth fields.

 

I hope this helps.


Please click Accept as Solution if my post answered your question. Like my answer? Consider giving it a Thumbs Up. Others seeking the same answers will be happy you did.

Helpful resources

Announcements

Celebrating the May Super User of the Month: Laurens Martens

  @LaurensM  is an exceptional contributor to the Power Platform Community. Super Users like Laurens inspire others through their example, encouragement, and active participation. We are excited to celebrated Laurens as our Super User of the Month for May 2024.   Consistent Engagement:  He consistently engages with the community by answering forum questions, sharing insights, and providing solutions. Laurens dedication helps other users find answers and overcome challenges.   Community Expertise: As a Super User, Laurens plays a crucial role in maintaining a knowledge sharing environment. Always ensuring a positive experience for everyone.   Leadership: He shares valuable insights on community growth, engagement, and future trends. Their contributions help shape the Power Platform Community.   Congratulations, Laurens Martens, for your outstanding work! Keep inspiring others and making a difference in the community!   Keep up the fantastic work!        

Check out the Copilot Studio Cookbook today!

We are excited to announce our new Copilot Cookbook Gallery in the Copilot Studio Community. We can't wait for you to share your expertise and your experience!    Join us for an amazing opportunity where you'll be one of the first to contribute to the Copilot Cookbook—your ultimate guide to mastering Microsoft Copilot. Whether you're seeking inspiration or grappling with a challenge while crafting apps, you probably already know that Copilot Cookbook is your reliable assistant, offering a wealth of tips and tricks at your fingertips--and we want you to add your expertise. What can you "cook" up?   Click this link to get started: https://aka.ms/CS_Copilot_Cookbook_Gallery   Don't miss out on this exclusive opportunity to be one of the first in the Community to share your app creation journey with Copilot. We'll be announcing a Cookbook Challenge very soon and want to make sure you one of the first "cooks" in the kitchen.   Don't miss your moment--start submitting in the Copilot Cookbook Gallery today!     Thank you,  Engagement Team

Announcing Power Apps Copilot Cookbook Gallery

We are excited to share that the all-new Copilot Cookbook Gallery for Power Apps is now available in the Power Apps Community, full of tips and tricks on how to best use Microsoft Copilot as you develop and create in Power Apps. The new Copilot Cookbook is your go-to resource when you need inspiration--or when you're stuck--and aren't sure how to best partner with Copilot while creating apps.   Whether you're looking for the best prompts or just want to know about responsible AI use, visit Copilot Cookbook for regular updates you can rely on--while also serving up some of your greatest tips and tricks for the Community. Check Out the new Copilot Cookbook for Power Apps today: Copilot Cookbook - Power Platform Community.  We can't wait to see what you "cook" up!    

Welcome to the Power Automate Community

You are now a part of a fast-growing vibrant group of peers and industry experts who are here to network, share knowledge, and even have a little fun.   Now that you are a member, you can enjoy the following resources:   Welcome to the Community   News & Announcements: The is your place to get all the latest news around community events and announcements. This is where we share with the community what is going on and how to participate.  Be sure to subscribe to this board and not miss an announcement.   Get Help with Power Automate Forums: If you're looking for support with any part of Power Automate, our forums are the place to go. From General Power Automate forums to Using Connectors, Building Flows and Using Flows.  You will find thousands of technical professionals, and Super Users with years of experience who are ready and eager to answer your questions. You now have the ability to post, reply and give "kudos" on the Power Automate community forums. Make sure you conduct a quick search before creating a new post because your question may have already been asked and answered. Galleries: The galleries are full of content and can assist you with information on creating a flow in our Webinars and Video Gallery, and the ability to share the flows you have created in the Power Automate Cookbook.  Stay connected with the Community Connections & How-To Videos from the Microsoft Community Team. Check out the awesome content being shared there today.   Power Automate Community Blog: Over the years, more than 700 Power Automate Community Blog articles have been written and published by our thriving community. Our community members have learned some excellent tips and have keen insights on the future of process automation. In the Power Automate Community Blog, you can read the latest Power Automate-related posts from our community blog authors around the world. Let us know if you'd like to become an author and contribute your own writing — everything Power Automate-related is welcome.   Community Support: Check out and learn more about Using the Community for tips & tricks. Let us know in the Community Feedback  board if you have any questions or comments about your community experience. Again, we are so excited to welcome you to the Microsoft Power Automate community family. Whether you are brand new to the world of process automation or you are a seasoned Power Automate veteran - our goal is to shape the community to be your 'go to' for support, networking, education, inspiration and encouragement as we enjoy this adventure together.     Power Automate Community Team

Hear what's next for the Power Up Program

Hear from Principal Program Manager, Dimpi Gandhi, to discover the latest enhancements to the Microsoft #PowerUpProgram, including a new accelerated video-based curriculum crafted with the expertise of Microsoft MVPs, Rory Neary and Charlie Phipps-Bennett. If you’d like to hear what’s coming next, click the link below to sign up today! https://aka.ms/PowerUp  

Tuesday Tip | How to Report Spam in Our Community

It's time for another TUESDAY TIPS, your weekly connection with the most insightful tips and tricks that empower both newcomers and veterans in the Power Platform Community! Every Tuesday, we bring you a curated selection of the finest advice, distilled from the resources and tools in the Community. Whether you’re a seasoned member or just getting started, Tuesday Tips are the perfect compass guiding you across the dynamic landscape of the Power Platform Community.   As our community family expands each week, we revisit our essential tools, tips, and tricks to ensure you’re well-versed in the community’s pulse. Keep an eye on the News & Announcements for your weekly Tuesday Tips—you never know what you may learn!   Today's Tip: How to Report Spam in Our Community We strive to maintain a professional and helpful community, and part of that effort involves keeping our platform free of spam. If you encounter a post that you believe is spam, please follow these steps to report it: Locate the Post: Find the post in question within the community.Kebab Menu: Click on the "Kebab" menu | 3 Dots, on the top right of the post.Report Inappropriate Content: Select "Report Inappropriate Content" from the menu.Submit Report: Fill out any necessary details on the form and submit your report.   Our community team will review the report and take appropriate action to ensure our community remains a valuable resource for everyone.   Thank you for helping us keep the community clean and useful!

Users online (2,737)